Biometric Identification System with Distributed Template Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current biometric authentication systems face challenges in implementing non-repudiation processes for critical transactions, particularly in preventing tampering and ensuring secure storage and transmission of biometric data, which hinders their widespread adoption for national and local security, e-commerce, and financial applications.

Innovation Solution

A personalized biometric identification and non-repudiation system that utilizes low-latency bio print readers owned by users, a TRUST server for unidirectional non-Internet based communication, and a three-step process of capturing, personalizing, and registering biometric data to generate a Bio-print identification Number (BiN) and User identification Number (UiN), ensuring secure storage and authentication without central data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric prints are stored at a central location for authentication, then user authentication can be performed, but security risks increase due to potential compromise of central repositories

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric template storage from the central server and places it in a distributed manner across multiple secure locations including user devices and authorized entities. This extraction eliminates the single point of failure and reduces the security risk associated with centralized storage while maintaining authentication reliability through distributed verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The biometric authentication system is segmented into multiple independent components: biometric capture at user device, template extraction and storage at distributed locations, and authentication verification at authorized entities. This segmentation prevents compromise of the entire system if one component is breached, while maintaining overall authentication reliability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If specialized biometric scanner hardware is deployed at each transaction point, then authentication accuracy improves, but device complexity and cost increase

Engineering Contradiction:
Improvebiometric capture precisionVSAvoidhardware complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses universal biometric capture devices that can function across multiple platforms and transaction types. The same device can capture biometric data for authentication, enrollment, and verification purposes, eliminating the need for specialized hardware at each transaction point while maintaining measurement precision through standardized capture protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of requiring specialized hardware at each transaction point, the system creates and distributes digital copies of biometric templates to authorized entities. These templates can be verified using standard computing devices without requiring the original specialized capture hardware, thereby reducing device complexity while maintaining authentication accuracy.

Inventive Principle:
Principle #26Copying

3Ease of operation

If biometric prints are transmitted over the Internet for authentication, then remote authentication is enabled, but security risks increase due to potential interception or tampering

Engineering Contradiction:
Improveremote authentication capabilityVSAvoiddata transmission risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system extracts and transmits only the essential authentication elements (biometric templates and derived credentials) over secure channels, rather than transmitting raw biometric prints. This extraction minimizes the security risk during transmission while enabling remote authentication through secure protocol implementation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements preliminary security measures including encryption, digital signatures, and secure key management before biometric data leaves the user device. These preliminary anti-actions protect against interception and tampering during Internet transmission, enabling safe remote authentication.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2648163B1A personalized biometric identification and non-repudiation system
Publication Date: 2020.02.12 TATA CONSULTANCY SERVICES LTD
  • EP2648163B1 patent drawingFigure 1
  • EP2648163B1 patent drawingFigure 2

AI summary

A system and a method for providing a personalized biometric identification system to facilitate in securing critical transactions have been disclosed. The system 100 includes a server 102 which captures pre-designated biometric prints of a user, personalizes them and registers them on a bio print reader 126, owned by the user, over a unidirectional non-Internet based channel. The system 100 overcomes the challenges involved in employing biometrics as a part of non-repudiation process for authorizing Internet based critical transactions for multiple entities by assuring the safety of the biometric prints of the users and eliminating additional hardware requirements.